Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2026-57105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20522+
HIGH 7.8
CVE-2026-54981
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a securit…
Python
No fix yet
HIGH 7.8
CVE-2026-54984
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.5
CVE-2026-54113
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 5.5
CVE-2026-54123
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l…
Defender For Endpoint
No fix yet
CRITICAL 9.4
CVE-2026-50516
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
HIGH 8.8
CVE-2026-49179
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex…
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.0
CVE-2026-50472
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
HIGH 7.2
CVE-2026-47299
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p…
Azure Monitor Agent
1.43+
HIGH 7.8
CVE-2026-42976
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
MEDIUM 6.5
CVE-2026-40375
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Dynamics 365 Business Central 2024
26.0.50788 / 27.0.50789+
MEDIUM 6.5
CVE-2026-47285
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose…
Visual Studio Code
Fix available
CRITICAL 9.6
CVE-2026-70332
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Online
No fix yet
CRITICAL 9.1
CVE-2026-68823
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Azure Confidential Ledger
No fix yet
CRITICAL 10.0
CVE-2026-65667
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Teams
No fix yet
HIGH 8.8
CVE-2026-65668
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Purview Ediscovery
No fix yet
CRITICAL 10.0
CVE-2026-63508
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Planetary Computer
No fix yet
CRITICAL 9.8
CVE-2026-62873
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Windows Admin Center
No fix yet
CRITICAL 9.6
CVE-2026-62896
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Teams
No fix yet
HIGH 7.5
CVE-2026-62918
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Teams
No fix yet
CRITICAL 10.0
CVE-2026-62836
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg…
Azure Sql Managed Instance
No fix yet
CRITICAL 9.9
CVE-2026-62830
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Azure Sre Agent
No fix yet
CRITICAL 9.9
CVE-2026-59115
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Entra Provisioning Service
No fix yet
CRITICAL 9.3
CVE-2026-59118
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Power Apps
No fix yet
CRITICAL 10.0
CVE-2026-56162
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Azure Sql Database
No fix yet
CRITICAL 9.9
CVE-2026-50515
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Azure Service Bus
No fix yet
CRITICAL 9.6
CVE-2026-56161
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Azure Logic Apps
No fix yet
CRITICAL 9.9
CVE-2026-50481
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Azure Active Directory
No fix yet
HIGH 8.8
CVE-2026-49163
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev…
Application Insights Profiler
No fix yet
CRITICAL 9.6
CVE-2026-66321
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…
Edge Chromium
151.0.4129.59+